Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




basics logo Security Basics mailing list archives

Re: DMZ Web Servers
From: krymson () gmail com
Date: Mon, 8 Sep 2008 12:55:32 -0600

Typically only traffic necessary for your web server to talk to the database server is necessary. This would be done on 
the Network layer (tcp/udp ports), instead of MACs on the second layer. Allowing entire IPs to talk to each other is 
too much.

I find that it is easiest to turn your firewall or router all the way closed and log denies. As you attempt to use the 
database server from the web server, start opening up the IP/port combinations as necessary while remembering to also 
check the same on the return path.

If, like a previous responder, you'd be worried about SQL injection, then you'd be worried about something beyond your 
infrastructure layout.

(Fine, there are things you can put in between your web server and database server to alert on mischievous traffic 
between the two, but I posit that solution is rare and not served when you [should] have that traffic encrypted anyway.)


<- snip ->
I would like to know any suggestions or ideas how some infrastructures
currently setup their Web Servers in the DMZ and connect back to an
Oracle or MSSQL backend on the inside. I was thinking of just allowing
specific IPs and MACs, but any other help would be greatly appreciated.

Thanks!
Rico


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]